NIST updates incident response guidance: plan beyond mitigation

Connect protection settings, incident records and recovery into a repeatable process.

Contents of this article

Integrating response with risk management

NIST published SP 800-61 Rev.3 on April 3, 2025, integrating incident response with CSF 2.0 risk management. It is an organizational framework rather than instructions for a particular protection console.

Keep records that support collaboration

Provide the first observed time and time zone, affected address, protocol and port, symptoms and sanitized examples. Include recent DNS, certificate, policy and application changes so teams can distinguish configuration failures from attacks.

Define when each stage is complete

Starting mitigation is not the same as recovery. Define exit conditions for confirmation, containment, restoration and review, such as stable critical endpoints, drained queues and reviewed temporary rules. Set timing targets from business requirements.

Convert lessons into recurring checks

Assign confirmed issues to owners with a deadline and verification method. Recheck the measures before later releases, especially when adding domains or ports or replacing an origin.

References

NIST SP 800-61 Rev.3

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support